Radius

Just wondering… Is it possible to use radius but still have the secrets entered and enabled so if radius goes down, the default secrets could take over?

From what I have seen, local secrets are default over radius so I have to keep the secrets disabled so radius can authenticate and if radius goes down I have to manually go in and enable them.

Thanks

Yes, firstly local configuration is consulted then RADIUS server database.
You can add backup RADIUS server, or try to automate described actions (enabling secrets) with scripts.